Freescout

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 46
    Known Exploited: 0
    8
    Critical Level Threats
    15
    High Level Threats
    20
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-40565

    FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-40498

    FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-40497

    FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)

    Last Modified: Apr 23, 2026
    Published: Apr 21, 2026

    CVE-2026-40496

    FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force

    Last Modified: Apr 23, 2026
    Published: Apr 21, 2026

    CVE-2026-35584

    FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration

    Last Modified: Apr 16, 2026
    Published: Apr 07, 2026
    Items Per Page
    Freescout Vulnerabilities & Security CVEs | CVE-DB